Subversion compiled with gnome-wallet support, but not kwallet support

Bug #466078 reported by Scott Kitterman
274
This bug affects 4 people
Affects Status Importance Assigned to Milestone
subversion (Ubuntu)
Fix Released
High
Unassigned

Bug Description

Binary package hint: subversion

svn 1.6 now supports gnome-wallet and kwallet. The Ubuntu package only has gnome-wallet support compiled in.

Svn will ask for a gnome-wallet password even when the package isn't installed:

$ svn ci -m "Update version and description in setup.py"
Sending trunk/setup.py
Password for 'default' GNOME keyring:

Given that the documentation http://svnbook.red-bean.com/ described the addition of wallet support as a fix for a security deficiency, I think the lack of kwallet support is a security issue.

ProblemType: Bug
Architecture: i386
Date: Sat Oct 31 01:13:40 2009
DistroRelease: Ubuntu 9.10
Package: subversion 1.6.5dfsg-1ubuntu1
ProcEnviron:
 LANGUAGE=
 LANG=en_US.UTF-8
 SHELL=/bin/bash
ProcVersionSignature: Ubuntu 2.6.31-14.48-generic
SourcePackage: subversion
Uname: Linux 2.6.31-14-generic i686
XsessionErrors:
 (polkit-gnome-authentication-agent-1:2614): GLib-CRITICAL **: g_once_init_leave: assertion `initialization_value != 0' failed
 (<unknown>:3073): Gdk-CRITICAL **: gdk_window_get_origin: assertion `GDK_IS_WINDOW (window)' failed
 (<unknown>:3073): Gdk-WARNING **: GdkWindow 0x4e00003 unexpectedly destroyed
 (<unknown>:19734): Gdk-CRITICAL **: gdk_window_get_origin: assertion `GDK_IS_WINDOW (window)' failed

Revision history for this message
Scott Kitterman (kitterman) wrote :
security vulnerability: no → yes
Changed in subversion (Ubuntu):
importance: Undecided → High
Changed in subversion (Ubuntu):
status: New → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package subversion - 1.6.6dfsg-2ubuntu1

---------------
subversion (1.6.6dfsg-2ubuntu1) lucid; urgency=low

  * Merge from debian unstable (LP: #483953).
    Includes enabling kwallet support (LP: #481792, #466078).
    Remaining changes:
    - Create pot file on build.
    - Build a python-subversion-dbg package.
    - (Build-)depend on default-jre-headless/-jdk.
    - Do not apply java-build patch.
    - debian/rules: Manually create the doxygen output directory, otherwise
      we get weird build failures when running parallel builds.
    - Disable the serf backend because serf is in universe.
  * Amend the XS-Python-Version line to ">= 2.4" rather than explicit
    versions (only building for 2.6 in Lucid since that is the onl Python in
    Lucid).

subversion (1.6.6dfsg-2) unstable; urgency=low

  * Update svn-bisect (Closes: #535234), fix bugs, add features,
    and write a manpage. Also mention it in the subversion-tools
    Description. (Closes: #535187)
  * Move from db4.7 to db4.8, tracking apr-util. (Closes: #557457)
  * Move the example XSL and CSS files for mod_dav_svn to
    /usr/share/doc/libapache2-svn/examples/. (Closes: #553535)
  * patches/ruby-test-info: New patch to maybe address a FTBFS. (#545372)
    Thanks Michael Diers, Joe Swatosh and Stefan Sperling. I expect that
    this is not the only fix needed, but we shall see.
  * patches/16x-po: New patch: a couple translation updates from 1.6.7.
  * libsvn-java: depend on ${shlibs:Depends}, thanks Lintian.
  * python-subversion: Update an outdated Lintian override.
  * libsvn1: Add a handful of Lintian overrides.

subversion (1.6.6dfsg-1) unstable; urgency=low

  * New upstream release.
    - Reintroduce svn_load_dirs.pl: Dolby has agreed to an explicit free
      software license. Thanks Blair Zajac for following up on this.
    - patches/ruby-test-core: New patch from upstream to fix a new failure
      in the ruby testsuite.
  * Standards-Version 3.8.3 (no changes).
  * control: Some housecleaning: remove some Conflicts/Replaces/Provides
    that haven't been needed since etch.
  * patches/build-fixes: add a small fix for parallel builds.
    (Closes: #531369, #543110)
  * patches/svn2cl-upstream: New patch to fix the XSL to better comply
    with XML standards. (Closes: #546990)
  * Enable kwallet support. (Closes: #539564)
    - patches/kwallet-wid: New patch based very loosely on upstream work, to
      let the kwallet library know your terminal's Window ID, if available.
    - patches/apr-abi, patches/rpath: Fix the LINK_CXX target, now that
      we're finally using it.
  * Set dependency_libs='' in all .la files (Closes: #544877), as per:
    http://lists.debian.org/debian-devel/2009/08/msg00783.html
 -- Max Bowsher <email address hidden> Fri, 11 Dec 2009 23:48:13 +0000

Changed in subversion (Ubuntu):
status: Confirmed → Fix Released
Revision history for this message
Dennis Schridde (devurandom) wrote :

When will this reach Ubuntu 9.10 / Karmic?

Revision history for this message
Scott Kitterman (kitterman) wrote : Re: [Bug 466078] Re: Subversion compiled with gnome-wallet support, but not kwallet support

It won't. I tried this during Karmic development and it doesn't work with the version we have in Karmic.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.